983b7eff4b1c516c9cb7bb56cc1399216a127d51 max Wed Aug 19 04:02:39 2026 -0700 address v503 preview1 code review (#38141): escaping and oauth fixes Fixes the six items Brian raised reviewing the XSS sweep (#38057) and the BLAT-results group work (#38086): - hgGenome/configure.c, hgPal.c: drop htmlEncode() on cartWebStart title args; cartWebStart already escapes the title, so this was double-escaping. - hgSession.c doReSaveSession: htmlEncode the user name and pass the encoded name to getSessionLink (same fix already applied at line 1544). - hgUserSuggestion.c printInvalidForm: cgiEncode the five cart values echoed into the mailto: href (reachable on the robot/captcha path). - hgSearch.c: cgiEncode db for the hgTracks URL query parameter instead of reusing the JSON-escaped copy meant for the JS string literal. - hgLogin.c oauthReturn: clone oauth_provider before cartRemove frees it, so the later oauthFetchIdentity call is not a read-after-free. - customFactory.c checkGroup: only accept group=blat when blatResultsGroup is on, matching hgTracks; otherwise the group is never created and the track would orphan into 'other'. refs #38141, refs #38057, refs #38086 diff --git src/hg/hgSession/hgSession.c src/hg/hgSession/hgSession.c index 96fab2a9824..2494423d8b5 100644 --- src/hg/hgSession/hgSession.c +++ src/hg/hgSession/hgSession.c @@ -1892,32 +1892,32 @@ // Some old sessions reference databases that are no longer present, and that triggers an errAbort // when cartHideDefaultTracks calls hgTrackDb. Don't let that stop the process of updating other // stuff in the session. struct errCatch *errCatch = errCatchNew(); if (errCatchStart(errCatch)) cartHideDefaultTracks(cart); errCatchEnd(errCatch); if (errCatch->gotError) fprintf(stderr, "doReSaveSession: Error from cartHideDefaultTracks: '%s'; Continuing...", errCatch->message->string); errCatchFree(&errCatch); struct dyString *dyMessage = dyStringNew(1024); dyStringPrintf(dyMessage, "Re-saved settings from user %s's session %s " "that %s be shared with others. %s %s", - userName, htmlEncode(sessionName), (sharingLevel ? "may" : "may not"), - getSessionLink(userName, encSessionName), + htmlEncode(userName), htmlEncode(sessionName), (sharingLevel ? "may" : "may not"), + getSessionLink(encUserName, encSessionName), getSessionEmailLink(encUserName, encSessionName)); cartCheckForCustomTracks(cart, dyMessage); int useCount = saveCartAsSession(conn, encUserName, encSessionName, sharingLevel); if (useCount <= INITIAL_USE_COUNT) errAbort("Expected useCount of at least %d after re-saving session for " "userName='%s', sessionName='%s', but got %d", INITIAL_USE_COUNT+1, encUserName, encSessionName, useCount); hDisconnectCentral(&conn); return dyStringCannibalize(&dyMessage); } // ====================================== void prepBackGroundCall(char **pBackgroundProgress, char *cleanPrefix) /* fix cart and save state */